Sr Manager, IT Cybersecurity Governance, Risk & Compliance
Manager
Data Security
Facilities Management
Governance And Compliance
GRC
Information Security
InfoSec
Management
Project Management
Risk & Compliance
Risk Governance
Risk Management
Security
Security Clearance
Security Compliance
Security Governance
Security Operations
Security Standards
Security Standards Compliance
ServiceNow
Job Description
American Airlines is hiring a senior leader to run IT cybersecurity governance, risk, and compliance across the enterprise in Fort Worth, TX (onsite).
Responsibilities
- Set direction for cybersecurity governance capabilities, ensuring policies, standards, control expectations, and risk management practices are practical, scalable, clearly owned, and aligned to enterprise priorities.
- Lead cybersecurity products, services, and enterprise capabilities by shaping roadmaps, prioritizing investments, tracking outcomes, and ensuring delivery supports risk reduction, regulatory readiness, and operational effectiveness.
- Convert cybersecurity strategy into actionable priorities, roadmaps, operating rhythms, and measurable outcomes; partner with cyber leaders to ensure work is prioritized, resourced, governed, and delivered against commitments.
- Provide leadership and direction for the Cybersecurity Chief of Staff function, supporting leadership cadence, executive communications, decision support, cross-functional coordination, and follow-through on key actions.
- Oversee cybersecurity work intake and execution planning, including prioritization, resource planning, budget tracking, financial forecasting, and portfolio reporting to improve transparency and accountability.
- Partner with Cybersecurity, Technology, Legal, Finance, Audit, Privacy, and business teams to align risk and compliance activities, support regulatory obligations, and provide outcome-focused reporting to senior leadership.
- Lead, coach, and develop team members and managers; drive strong collaboration, ownership, sound judgment, accountability, and consistent delivery across complex initiatives.
Requirements
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management, Compliance, Audit, or a related discipline, or equivalent experience/training.
- Experience delivering and leading cybersecurity, IT, risk management, compliance, audit, governance, or related activities.
- Strong leadership background overseeing cybersecurity governance, risk management, compliance, portfolio management, or similar enterprise capabilities.
- Ability to set strategic direction, define capability roadmaps, prioritize work, and align cyber products and services to enterprise risk, regulatory, and business objectives.
- Experience leading cyber work management, operating rhythms, resource planning, budget oversight, financial tracking, and portfolio reporting across complex organizations.
- Working knowledge of cybersecurity, risk, compliance, and control frameworks including NIST, ISO 27001, PCI DSS, SOX, SOC 2, CMMC, GDPR, or similar standards.
- Proven capability to translate complex cybersecurity risks, priorities, and investments into executive-level communications, decision materials, metrics, and reporting.
- Demonstrated ability to lead cross-functional teams and influence senior stakeholders across cybersecurity, technology, finance, legal, audit, privacy, compliance, and business.
- Strong judgment, ownership, and executive presence, including driving alignment, resolving ambiguity, escalating decisions appropriately, and ensuring follow-through.
- Experience building and developing high-performing teams, including setting expectations, strengthening accountability, and improving delivery across multiple workstreams.
- 7+ years experience in cybersecurity, information technology, risk management, compliance, audit, governance, or a closely related field.
- 5+ years leadership experience.
- 8+ years in the related domain and 6+ years leadership experience preferred.
Technologies
- NIST
- ISO 27001
- PCI DSS
- SOX
- SOC 2
- CMMC
- GDPR
- CISM
- CISSP
- CRISC
- CISA
- CDPSE
- PMP
Benefits
- 20+ Employee Business Resource Groups focused on connecting team members to customers, suppliers, communities, and shareholders, supporting personal growth and creating an inclusive work environment.
- 20+ Team Member Resource Groups focused on connecting team members to customers, suppliers, communities and shareholders, supporting personal growth and creating an inclusive work environment.
Additional experience or credentials (preferred)
- Experience leading cybersecurity governance, risk management, compliance, control management, or related enterprise programs, including setting priorities, defining outcomes, and improving program maturity.
- Experience overseeing security audits, assessments, control assurance activities, remediation governance, and executive reporting to support clear ownership and timely risk reduction.
- Relevant certifications preferred, such as CISM, CISSP, CRISC, CISA, CDPSE, ISO 27001, PMP, or comparable certifications.
Similar Jobs
$115k - $132k/yr
Full time
Cybersecurity Tools
Iam Identity Governance
Identity and Access Management